Froxlor是Froxlor组织开源的一款服务器管理软件。 Froxlor 2.3.7之前版本存在授权问题漏洞,该漏洞源于API认证路径未检查type_2fa、验证TOTP代码或调用FroxlorTwoFactorAuth,导致攻击者获取API密钥和机密后无需第二因素即可调用API函数,暴露或修改客户数据、域名、电子邮件和FTP账户、数据库、DNS记录和证书材料。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-62988 | 9.0 CRITICAL | Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints |
| CVE-2026-54347 | 8.7 HIGH | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover |
| CVE-2026-54348 | 7.2 HIGH | Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Dat |
| CVE-2026-55593 | 6.5 MEDIUM | Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery |
| CVE-2026-54543 | 5.4 MEDIUM | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields |
No comments yet